PCNSA Device Management and Services Practice Question
A security administrator needs to restrict access to the firewall's web management interface to only the IP address 10.1.1.100. The administrator logs into the firewall and navigates to Device > Setup > Management. Which configuration should be modified?
⚠ Common exam trap
Many exam-takers confuse management plane access restrictions with security policy rules, which apply only to data plane traffic.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Management Interface Settings: Add 10.1.1.100/32 to the Permitted IP Addresses list.
The Permitted IP Addresses list under Device > Setup > Management > Management Interface Settings is specifically designed to restrict management access to specified IP addresses. Adding 10.1.1.100/32 ensures only that host can connect to the web interface. Other settings, such as admin roles or service ports, do not provide IP-based restriction.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Device > Setup > Services: Configure a security policy rule to allow only 10.1.1.100 to the management interface.
Why it's wrong here
Security policy rules apply to traffic passing through the firewall, not to traffic destined to the management interface. Management plane access is controlled separately via the Management Interface Settings. You cannot use a security policy rule to restrict management access. Therefore, this option is not correct.
- ✗
Administrative Accounts: Create a new admin role with read-only access for 10.1.1.100.
Why it's wrong here
Administrative accounts define user roles and permissions, not source IP restrictions. Creating a role does not limit access based on IP address. While you can assign roles to users, the ability to log in from a specific IP is controlled by the Permitted IP Addresses list. Therefore, this option does not achieve the goal.
- ✓
Management Interface Settings: Add 10.1.1.100/32 to the Permitted IP Addresses list.
Why this is correct
The Permitted IP Addresses list under Management Interface Settings allows you to specify which IP addresses can access the management interface. Adding 10.1.1.100/32 restricts access to only that IP. This is the correct place to enforce such a restriction. Other settings do not control management access at the interface level.
- ✗
Management Interface Settings: Enable HTTP and HTTPS on the management interface.
Why it's wrong here
Enabling HTTP and HTTPS allows web access to the management interface, but it does not restrict access to a specific IP address. It broadens access rather than narrowing it. To restrict to a single IP, you need to use the Permitted IP Addresses list. Thus, this option is incorrect.
Go deeper
Related to this question
About these practice questions
This PCNSA question is part of Courseiva's 385-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official Palo Alto Networks exam blueprint
This PCNSA practice question is part of Courseiva's free Palo Alto Networks certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the PCNSA exam.